decrypted · 14 september 2026 · vulnerabilities and patching · uk policy and law · surveillance and privacy

Microsoft's Windows Defender patch didn't survive the week

Microsoft's September Patch Tuesday closed a Windows Defender flaw that let a local attacker grab SYSTEM-level access. On 9 September, days after that fix shipped, the anonymous researcher who found the original flaw published a working bypass of Microsoft's own patch. The new exploit, called ShieldCrash, does not care that the machine in front of it is fully patched. It is the latest round in a running fight between one researcher and Microsoft, and it says more about how software gets fixed than any single vulnerability does.

A lock changed, not the door

In August the researcher, who goes by Nightmare Eclipse (also known as Chaotic Eclipse or MSNightmare), published a proof of concept called ShieldBreak for a Defender privilege escalation bug catalogued as CVE-2026-69414. Microsoft patched it this month. Within days, Nightmare Eclipse showed that under specific conditions the same underlying problem could still be triggered, just through a different route. ShieldCrash lets an attacker who already has a foothold on a machine read arbitrary files with SYSTEM privileges, including the SAM database, enough to pull password hashes for offline cracking. It is not, by the researcher's own account, a full remote takeover: there is no arbitrary write and no shell. But on a "fully patched" Windows 10, 11 or Server box, that is a meaningful hole for anyone who already has a user-level foothold, which is most ransomware crews by the time they start trying to escalate.

Think of ShieldBreak as a badly fitted lock on a restricted door. Microsoft's patch swapped the lock. ShieldCrash shows the door frame itself was never fixed, so a differently shaped bypass gets through regardless of which lock is fitted. This is, by the researcher's count, at least the ninth Defender-related zero-day dropped since April, part of an increasingly personal dispute with Microsoft over its bug bounty and disclosure practices. Microsoft had not commented publicly on ShieldCrash at the time of writing, and has previously warned of legal action against "malicious activity causing real harm" to customers, language widely read as aimed at this researcher.

The Secure by Design lesson

Whatever you make of the researcher's methods, the pattern is the lesson. Microsoft keeps patching the specific proof of concept in front of it rather than the class of bug underneath, and keeps getting bypassed within days by the same person probing the same subsystem. Secure by Design means fixing the design flaw that makes a whole family of bugs possible, not shipping a fix narrow enough to route around. UK organisations should take two things from this: first, "fully patched" is not a security control on its own, particularly for endpoint protection software that is itself a high-value target. Second, defences that assume an attacker already has a foothold, least-privilege accounts, monitoring for SAM access, EDR tuned to catch credential dumping, matter more than patch cadence alone while the vendor is still catching up with its own fixes.

Also this week

The government has set out plans to force Apple and Google to build age verification into smartphones sold in the UK, rather than leaving it to individual apps. Culture Secretary Lisa Nandy told Parliament on 9 September that the aim is to make it "impossible" for under-18s to take, send or view nude images, with protections on by default for child accounts and adults verifying their age, potentially via ID or a credit card, to switch them off. It follows three months of talks with Apple and Google. Building the check into the device rather than the app is a genuine design improvement on today's patchwork of third-party age verification services, each holding its own copy of your ID. But moving the check to the OS also means the OS vendor decides what counts as restricted content and who gets to see it, and officials have not yet said how the scanning works or what happens to the data it generates.

The Cyber Security and Resilience Bill entered committee stage in the House of Lords on 1 September, and for the first time brings managed service providers into scope as a distinct regulated category, alongside data centres as newly designated critical infrastructure. That is a direct response to how often one compromised MSP turns into every customer it touches getting breached at once. The timing is apt: this week a ransomware group calling itself Vexy claimed an attack on Strad Solutions, a UK provider of cloud hosting and managed IT services, threatening to leak data unless it pays. Strad Solutions has not confirmed the claim, and it should be treated as exactly that, a claim, until it does. But it is a fair illustration of why the Bill's drafters decided a supplier's own sector should no longer determine whether it gets regulated.

Sources

If any of this touches your systems and you would like a second opinion, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.